2026-08-17
Added
Regulated entities must implement systems to mitigate risks associated with Politically Exposed Persons (PEPs), their family members, and close associates, applying these requirements regardless of the individual's geographical location. The guidance defines PEPs under Section 20 of POCA and mandates enhanced due diligence, senior management sign-off for business relationships, and independent verification of source of wealth and funds. Entities must maintain risk-sensitive monitoring for at least 12 months after a PEP ceholds their function and apply sector-specific controls for Trust & Company Services Providers and Banks to address vulnerabilities in corporate structures and transaction monitoring.
Get GFSC alerts — same-day email on every new publication.
www.gfsc.gi
7. Politically Exposed Persons
AML/CFT/CPF Guidance Notes
August 2026
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 2
Table of Contents
7.1 Measures Applicable to Politically Exposed Persons........................................................................ 3
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 3
7.1 Measures Applicable to Politically Exposed Persons
AML/CFT/CPF Requirements
R22 A regulated entity is required to implement adequate systems and controls to mitigate any risk associated with establishing business relationships with Politically Exposed Persons, or their family members and close associates. R23 A regulated entity is required to take into account the continuing risk posed by a PEP, close associate and family member for at least 12 months after they cease to hold the prominent public function. Guidance
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 4 or a natural person who has sole beneficial ownership of a legal entity, legal arrangement or similar that is known to have been set up for the benefit of a PEP.
5. POCA and these Guidance Notes do not draw a distinction between foreign and domestic PEPs.
Therefore, all individuals identified as a PEP, irrespective of geographical location, must be subject to the same requirements outlined in POCA and these Guidance Notes.
6. A regulated entity is obliged to identify all natural persons during the establishment of a
business relationship to verify whether they fall within the definition of a PEP, close associate or family member. A regulated entity should determine the most appropriate method to identify PEPs dependent on the size and nature of the products and services it provides. A regulated entity must also have controls in place to determine whether an individual becomes a PEP during the course of a business relationship.
7. A regulated entity must set out within its risk management framework, its risk appetite
concerning PEPs, close associates and family members and must have documented clear guidelines for the treatment of PEP clients in line with POCA and these Guidance Notes.
8. A regulated entity must apply enhanced due diligence and enhanced ongoing monitoring
measures to all business relationships where a PEP, close associate or family member has been identified. The level of enhanced due diligence undertaken must be commensurate to the risk posed by the PEP, close associate or family member. For further guidance on the application of enhanced due diligence and enhanced ongoing monitoring measures, please refer to the “Customer Due Diligence” and “Ongoing Monitoring” sections of these Guidance Notes.
9. A regulated entity must implement adequate systems and controls to mitigate the risks
associated with establishing and maintaining a business relationship with a PEP. The minimum requirements as defined by POCA are as follows:
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 5 function. A regulated entity must apply appropriate and risk-sensitive measures until such time as that person is deemed to pose no further PEP risks.
12. A regulated entity must ensure it obtains independent verification of the source of wealth and
funds for the proposed business relationship and ensure these are appropriately documented. The source of wealth should encompass the entire body of wealth of the PEP and the source of funds should demonstrate where the initial funding has derived from to establish the business relationship.
13. Independent verification means that the information received by the PEP can be evidenced by
obtaining independent proof of such, for example, open-source information, enhanced due diligence reports from a third-party provider or similar. The information received must be independent from the PEP in that it should not be from their own website or from a source where the PEP could have created the data themselves. For further guidance on the establishment and verification of source of funds and wealth, please refer to the “Customer Due Diligence” section of these Guidance Notes.
14. Once the nature and intended purpose, including the proposed number of transactions has
been obtained, a regulated entity must ensure it conducts more frequent ongoing monitoring of the business relationship in order to establish and verify that the intended purpose is in fact what the corporate vehicle is being used for in practice. Sector-Specific Guidance – Trust & Company Services Providers (TCSPs)
15. TCSPs present particular vulnerabilities which may be exploited as a vehicle to facilitate illicit
activity. Complex ownership structures can be utilised by PEPs in an attempt to conceal or hide the true nature of their ownership of an entity. It is imperative that all PEPs within a corporate structure are identified and verified during the onboarding of a new business relationship. In addition to this, the rationale and purpose/nature of the intended business relationship should also be sought and documented.
16. Where high risk jurisdictions are involved, TCSPs must note the increased risk and decide if this
falls within the risk appetite of the regulated entity. Certain jurisdictions have a higher propensity to be used for bribery and corruption and drug trafficking leading to potential ML, TF or PF. When onboarding PEP clients from high-risk jurisdictions, the TCSP should ensure it appropriately documents the rationale for establishing the business relationship and the additional measures that are in place to ensure that it is able to verify the purpose for the corporate entity. Sector-Specific Guidance - Banks
17. The accessibility of banking products makes the sector an attractive industry for PEPs to use as a
method to integrate illicit funds into the financial system and disguise the origin of the source of those funds. The use of various intermediaries and advisors for wealth management and private banking services may also increase the exposure to the risk of a bank being used to launder the proceeds of overseas bribery and corruption.
18. In these instances, mitigating actions may include increased transaction monitoring. This could
include taking into consideration the frequency and amounts of transactions, jurisdictions where transactions are made to/from and a determination of whether these are commensurate with the independently verified source of funds and wealth established at the inception of the business relationship.
Gibraltar Financial Services Commission AML/CFT/CPF Guidance Notes 6 Example - State Owned Enterprises
19. Generally, in the case of state-owned enterprises, the ultimate beneficial owner is the
government, which is therefore itself a PEP institution. In these instances, it is reasonable to assume that the source of wealth will be government funds. However, this does not remove the requirement to ensure that any additional funds or transactions are appropriately verified.
20. In these circumstances, the regulated entity would be expected to identify and verify all the
directors within the state-owned enterprise given they will likely exercise and maintain significant control over the entity. Given that a regulated entity may not be able to obtain the initial source of wealth/funds for the business relationship, this should be recorded accordingly within the client risk assessment. The extent of due diligence undertaken must be commensurate with the risk posed by the state-owned enterprise and the customer, country, product and interface risks must still be scored accordingly.
21. A regulated entity is required to carry out enhanced ongoing monitoring of these business
relationships to ensure that any changes to the intended nature and purpose of the business relationship, remain unchanged and in line with the expected customer activity.
Published by:
Gibraltar Financial Services Commission
PO Box 940
Suite 3, Ground Floor
Atlantic Suites
Europort Avenue
Gibraltar www.gfsc.gi
© 2017 Gibraltar Financial Services Commission
Read the rest free
Source: Gibraltar Financial Services Commission — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works